|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity Risk Management and Strategy
Under the oversight of our Board of Directors, we have implemented and maintain cybersecurity risk management policies and procedures that include processes for the identification, assessment and treatment through mitigation, transfer, avoidance and/or acceptance of cybersecurity risks.
Our cybersecurity risk management policies and procedures are informed by industry standards, and they are designed to address cybersecurity risks identified by external auditors and assessors, threat intelligence providers, internal stakeholders, vulnerability management programs and security management programs. Our team of information technology and cybersecurity professionals, led by our Chief Information Officer, or CIO, manages and maintains remediation strategies for identified cybersecurity risks and regularly reports on such risks to senior management, including our Governance Committee as described below.
Our cybersecurity risk management program is designed to be aligned with our business strategy. It shares common methodologies, reporting channels and governance processes that apply to other areas of enterprise risk, including legal, compliance, strategic, operational and financial risk. Key elements of our cybersecurity risk management program include:
Additionally, as a public company, we are subject to Sarbanes-Oxley (SOX) requirements and must undergo independent audits of Information Technology General Controls (ITGC) in support of Internal Control over Financial Reporting (ICFR). These audits assess key information security and cybersecurity risks in the environment that may affect the confidentiality, integrity and availability of financial reporting systems and data. If any control deficiencies that represent material cybersecurity risks were identified, those would be reported to the Audit Committee, and the results of these evaluations would be considered in the overall audit opinion for the Company.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
Under the oversight of our Board of Directors, we have implemented and maintain cybersecurity risk management policies and procedures that include processes for the identification, assessment and treatment through mitigation, transfer, avoidance and/or acceptance of cybersecurity risks.
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|These audits assess key information security and cybersecurity risks in the environment that may affect the confidentiality, integrity and availability of financial reporting systems and data.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance Related to Cybersecurity Risks
Our cybersecurity risk management program and related operations and processes are directed by our CIO. Currently, the CIO role is held by an individual who has been in the role for over nine years, has over 23 years of cybersecurity, information technology and systems engineering experience, and has advanced training in the field of technology.
The CIO is a member of our Governance Committee and regularly reports on cybersecurity risk management to other members of the Governance Committee comprised of the Company’s senior executive officers. The Governance Committee oversees the prioritization and escalation of risks from cybersecurity threats and is responsible for strategy, operations, financial management, information technology, compliance, legal, administration and corporate governance. The members of the Governance Committee collectively possess experience in these areas, including cybersecurity and risk management.
The Audit Committee oversees our management of cybersecurity risks. Pursuant to the Audit Committee charter, the Audit Committee is responsible for discussing cybersecurity-related risks with management and the steps management has taken to monitor and control such risks, including our risk assessment and risk management policies. The CIO regularly reports to the Audit Committee on our cybersecurity risks, and the chair of the Audit Committee reports on these discussions with the full Board of Directors. In addition, the CIO provides periodic reports to our Board of Directors.
|Cybersecurity Risk Role of Management [Text Block]
|
The CIO is a member of our Governance Committee and regularly reports on cybersecurity risk management to other members of the Governance Committee comprised of the Company’s senior executive officers. The Governance Committee oversees the prioritization and escalation of risks from cybersecurity threats and is responsible for strategy, operations, financial management, information technology, compliance, legal, administration and corporate governance. The members of the Governance Committee collectively possess experience in these areas, including cybersecurity and risk management.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
The Audit Committee oversees our management of cybersecurity risks. Pursuant to the Audit Committee charter, the Audit Committee is responsible for discussing cybersecurity-related risks with management and the steps management has taken to monitor and control such risks, including our risk assessment and risk management policies. The CIO regularly reports to the Audit Committee on our cybersecurity risks, and the chair of the Audit Committee reports on these discussions with the full Board of Directors. In addition, the CIO provides periodic reports to our Board of Directors.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|
While we have not, as of the date of this Report, experienced a cybersecurity incident that materially affected or is reasonably likely to materially affect our Company, including our business strategy, results of operations or financial condition, there can be no guarantee that we will not experience such an incident in the future. For information regarding cybersecurity risks that may materially affect our Company, see “Item 1A. Risk Factors” included in this Report.
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef